1 Commits

Author SHA1 Message Date
renovate[bot] 2742870f34 Update helm chart longhorn to v1.12.0 2026-06-02 16:51:47 +00:00
16 changed files with 8 additions and 290 deletions
+2 -2
View File
@@ -12,14 +12,14 @@ spec:
project: default
source:
repoURL: https://community-charts.github.io/helm-charts
targetRevision: 1.8.9
targetRevision: 1.8.7
chart: actualbudget
helm:
values: |
# Actual Budget configuration
image:
tag: "26.6.0"
tag: "26.3.0"
# Authentication configuration
login:
-12
View File
@@ -106,9 +106,6 @@ spec:
- name: blueprint-actualbudget
configMap:
name: authentik-blueprint-actualbudget
- name: blueprint-session
configMap:
name: authentik-blueprint-session
volumeMounts:
- name: blueprint-vault
mountPath: /blueprints/custom/vault-oidc.yaml
@@ -128,9 +125,6 @@ spec:
- name: blueprint-actualbudget
mountPath: /blueprints/custom/actualbudget-proxy.yaml
subPath: actualbudget-proxy.yaml
- name: blueprint-session
mountPath: /blueprints/custom/session-duration.yaml
subPath: session-duration.yaml
ingress:
enabled: true
ingressClassName: nginx
@@ -162,9 +156,6 @@ spec:
- name: blueprint-actualbudget
configMap:
name: authentik-blueprint-actualbudget
- name: blueprint-session
configMap:
name: authentik-blueprint-session
volumeMounts:
- name: blueprint-vault
mountPath: /blueprints/custom/vault-oidc.yaml
@@ -184,9 +175,6 @@ spec:
- name: blueprint-actualbudget
mountPath: /blueprints/custom/actualbudget-proxy.yaml
subPath: actualbudget-proxy.yaml
- name: blueprint-session
mountPath: /blueprints/custom/session-duration.yaml
subPath: session-duration.yaml
postgresql:
enabled: false
redis:
-21
View File
@@ -1,21 +0,0 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: bolletjestrui
namespace: argocd
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default
source:
repoURL: https://github.com/rubenhensen/k8scd.git
targetRevision: HEAD
path: bolletjestrui
destination:
server: https://kubernetes.default.svc
namespace: bolletjestrui
syncPolicy:
syncOptions:
- CreateNamespace=true
automated:
selfHeal: true
+1 -1
View File
@@ -15,7 +15,7 @@ spec:
sources:
- chart: external-secrets
repoURL: https://charts.external-secrets.io
targetRevision: 2.10.0
targetRevision: 0.10.7
destination:
server: https://kubernetes.default.svc
namespace: external-secrets
+1 -1
View File
@@ -16,7 +16,7 @@ spec:
sources:
- chart: longhorn
repoURL: https://charts.longhorn.io/
targetRevision: 1.7.3 # Replace with the Longhorn version you'd like to install or upgrade to
targetRevision: 1.12.0 # Replace with the Longhorn version you'd like to install or upgrade to
helm:
values: |
persistence:
-16
View File
@@ -11,22 +11,6 @@ Authentik is deployed as the central identity provider, providing OIDC and LDAP
- `blueprint-ldap.yaml` — LDAP provider (base DN: `DC=ldap,DC=goauthentik,DC=io`)
- `blueprint-mail-oidc.yaml` — OAuth2/OIDC provider for Stalwart mail
- `blueprint-vault-oidc.yaml` — OIDC provider for Vault
- `blueprint-argocd-oidc.yaml` — OIDC provider for ArgoCD
- `blueprint-freshrss-oidc.yaml` — OIDC provider for FreshRSS
- `blueprint-actualbudget-proxy.yaml` — Proxy provider for Actual Budget
- `blueprint-session-duration.yaml` — Session lifetime of the default authentication flow
## Session lifetime
Authentik ships the login stage of `default-authentication-flow` with
`session_duration: seconds=0`, i.e. the SSO session dies when the browser closes.
`blueprint-session-duration.yaml` raises this to 30 days for every app that uses
that flow (FreshRSS, ArgoCD, Vault, Actual Budget, mail).
The expiry is **absolute** — Authentik does not extend a session on activity. A
sliding window has to come from the application itself; FreshRSS does this via
`OIDC_SESSION_INACTIVITY_TIMEOUT` (see `freshrss/freshrss-deployment.yaml`), which
Apache mod_auth_openidc refreshes on every request.
## LDAP Outpost
-27
View File
@@ -1,27 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: authentik-blueprint-session
data:
session-duration.yaml: |
version: 1
metadata:
name: Session duration
entries:
# Overrides the login stage of the built-in `default-authentication-flow`,
# which every OIDC/proxy provider in this cluster authenticates against.
# authentik ships this stage with `session_duration: seconds=0`, which means
# "until the browser is closed" — that is why re-logins were so frequent.
#
# Note: authentik's session expiry is absolute (counted from login), it does
# not slide on activity. The sliding window lives in the applications, e.g.
# OIDC_SESSION_INACTIVITY_TIMEOUT in freshrss/freshrss-deployment.yaml.
- model: authentik_stages_user_login.userloginstage
state: present
identifiers:
name: default-authentication-login
attrs:
session_duration: days=30
# Uncomment to show a "Remember me on this device" checkbox that adds
# this offset on top of session_duration when ticked (0 = hidden).
# remember_me_offset: days=60
@@ -1,98 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
app: bolletjestrui
name: bolletjestrui
spec:
replicas: 1
selector:
matchLabels:
app: bolletjestrui
strategy:
type: Recreate
template:
metadata:
labels:
app: bolletjestrui
spec:
containers:
- image: ghcr.io/rubenhensen/bolletjestrui:main-10268f1
name: bolletjestrui
ports:
- containerPort: 3000
protocol: TCP
env:
- name: DATABASE_URL
value: /app/data/bolletjestrui.db
- name: ORIGIN
value: https://vic.rubenhensen.nl
- name: PROTOCOL_HEADER
value: x-forwarded-proto
- name: HOST_HEADER
value: x-forwarded-host
# GPX routes and profile photos (up to 20 MB); raise adapter-node's 512K default
- name: BODY_SIZE_LIMIT
value: "25M"
- name: TZ
value: Europe/Amsterdam
- name: SITE_PASSWORD
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: site_password
- name: ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: admin_password
- name: KEY_SECRET
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: key_secret
# Push notifications. optional:true is load-bearing: without it a missing
# key leaves the pod in CreateContainerConfigError and the site is down,
# which would make deploying this depend on the Vault entries landing
# first. The app already treats absent VAPID keys as "send nothing".
- name: VAPID_PUBLIC_KEY
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: vapid_public_key
optional: true
- name: VAPID_PRIVATE_KEY
valueFrom:
secretKeyRef:
name: bolletjestrui-secrets
key: vapid_private_key
optional: true
- name: VAPID_SUBJECT
value: mailto:ruben.hensen@protonmail.com
resources:
requests:
memory: "128Mi"
cpu: "50m"
limits:
memory: "512Mi"
cpu: "500m"
readinessProbe:
httpGet:
path: /login
port: 3000
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /login
port: 3000
initialDelaySeconds: 15
periodSeconds: 20
volumeMounts:
- mountPath: /app/data
name: data
restartPolicy: Always
volumes:
- name: data
persistentVolumeClaim:
claimName: bolletjestrui-data
-13
View File
@@ -1,13 +0,0 @@
apiVersion: v1
kind: Service
metadata:
labels:
app: bolletjestrui
name: bolletjestrui
spec:
ports:
- name: "3000"
port: 3000
targetPort: 3000
selector:
app: bolletjestrui
@@ -1,12 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
labels:
app: bolletjestrui
name: bolletjestrui-data
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 2Gi
-36
View File
@@ -1,36 +0,0 @@
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: bolletjestrui-secrets
spec:
secretStoreRef:
name: vault-backend
kind: ClusterSecretStore
refreshInterval: 15m
target:
name: bolletjestrui-secrets
creationPolicy: Owner
data:
- secretKey: site_password
remoteRef:
key: kv/bolletjestrui
property: site_password
- secretKey: admin_password
remoteRef:
key: kv/bolletjestrui
property: admin_password
- secretKey: key_secret
remoteRef:
key: kv/bolletjestrui
property: key_secret
# web-push keypair for the "de route is gekozen" notification.
# Generate once with `npx web-push generate-vapid-keys` and never rotate it:
# a new key invalidates every subscription on everyone's phone.
- secretKey: vapid_public_key
remoteRef:
key: kv/bolletjestrui
property: vapid_public_key
- secretKey: vapid_private_key
remoteRef:
key: kv/bolletjestrui
property: vapid_private_key
-27
View File
@@ -1,27 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: bolletjestrui-ingress
annotations:
cert-manager.io/cluster-issuer: prod-cluster-issuer
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/ssl-passthrough: "false"
# matches the app's BODY_SIZE_LIMIT: a bulk route import posts every GPX at once
nginx.ingress.kubernetes.io/proxy-body-size: "25m"
spec:
ingressClassName: nginx
rules:
- host: vic.rubenhensen.nl
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: bolletjestrui
port:
number: 3000
tls:
- secretName: letsencrypt-prod
hosts:
- vic.rubenhensen.nl
+2 -6
View File
@@ -10,7 +10,7 @@ records:
- name: "phocaslustrum"
expire: 300
type: A
content: "62.41.86.27"
content: "62.41.87.114"
- name: "ynab"
expire: 300
type: A
@@ -22,7 +22,7 @@ records:
- name: "ldap"
expire: 300
type: A
content: "62.41.86.27"
content: "62.41.87.114"
- name: "argocd"
expire: 300
type: A
@@ -59,10 +59,6 @@ records:
expire: 300
type: A
content: "46.224.26.65"
- name: "vic"
expire: 300
type: A
content: "46.224.26.65"
- name: "@"
expire: 300
type: MX
-14
View File
@@ -56,20 +56,6 @@ spec:
value: "openid email profile"
- name: OIDC_X_FORWARDED_HEADERS
value: X-Forwarded-Port X-Forwarded-Proto X-Forwarded-Host
# Session handling for the Apache mod_auth_openidc layer that guards /i/.
# Defaults are 5 min inactivity / ~7.5 h max, which is what caused the
# constant bounces back to authentik.
# Sliding window: refreshed on every request, so any visit within the
# period extends it by another 30 days.
- name: OIDC_SESSION_INACTIVITY_TIMEOUT
value: "2592000" # 30 days
# Hard cap, counted from login and never extended.
- name: OIDC_SESSION_MAX_DURATION
value: "7776000" # 90 days
# ":persistent" makes the session cookie survive a browser restart
# (its expiry tracks OIDC_SESSION_INACTIVITY_TIMEOUT).
- name: OIDC_SESSION_TYPE
value: "server-cache:persistent"
- name: TZ
value: Europe/Amsterdam
image: freshrss/freshrss:latest
+1 -2
View File
@@ -2,7 +2,7 @@
let
# Public IP of the home network where the k8s cluster ingress lives.
# Keep in sync with dns/domains/rubenhensen.nl.yaml.
homeIP = "62.41.86.27";
homeIP = "62.41.87.114";
# Hosts tunneled to the home k8s cluster. Each entry gets:
# * an SNI map entry for TCP passthrough on :443
@@ -20,7 +20,6 @@ let
"blog.rubenhensen.nl"
"serpbear.rubenhensen.nl"
"git.rubenhensen.nl"
"vic.rubenhensen.nl"
];
sniMapEntries =
+1 -2
View File
@@ -16,8 +16,7 @@
"kubernetes": {
"managerFilePatterns": [
"/apps/templates/.+\\.yaml$/",
"/serpbear/.+\\.yaml$/",
"/bolletjestrui/.+\\.yaml$/"
"/serpbear/.+\\.yaml$/"
]
},
"customManagers": [